7.5

CVE-2017-6672

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affected device. More Information: CSCvb99022 CSCvc16964 CSCvc37351 CSCvc54843 CSCvc63444 CSCvc77815 CSCvc88658 CSCve08955 CSCve14141 CSCve33870.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asr 5000 Series Software Version 19.3.5
Cisco ≫ Asr 5000 Series Software Version 19.3.11
Cisco ≫ Asr 5000 Series Software Version 19.3.12
Cisco ≫ Asr 5000 Series Software Version 19.6.0
Cisco ≫ Asr 5000 Series Software Version 19.6.3
Cisco ≫ Asr 5000 Series Software Version 19.6.6
Cisco ≫ Asr 5000 Series Software Version 20.1.v5
Cisco ≫ Asr 5000 Series Software Version 20.2.4
Cisco ≫ Asr 5000 Series Software Version 20.2.12
Cisco ≫ Asr 5000 Series Software Version 20.3.0
Cisco ≫ Asr 5000 Series Software Version 20.3.1
Cisco ≫ Asr 5000 Series Software Version 21.0.v1.66638
Cisco ≫ Asr 5000 Series Software Version 21.0.v2
Cisco ≫ Asr 5000 Series Software Version 21.1.0
Cisco ≫ Asr 5000 Series Software Version 21.1.2
Cisco ≫ Asr 5000 Series Software Version 21.1.m0.65710
Cisco ≫ Asr 5000 Series Software Version 21.1.m0.65921
Cisco ≫ Asr 5000 Series Software Version 21.1.m0.65931
Cisco ≫ Asr 5000 Series Software Version 21.1.m0.65986
Cisco ≫ Asr 5000 Series Software Version 21.1.v0
Cisco ≫ Asr 5000 Series Software Version 21.2.a0.65914
Cisco ≫ Asr 5000 Series Software Version 21.2.a0.65995
Cisco ≫ Asr 5000 Series Software Version 21.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.83% 0.761
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

http://www.securityfocus.com/bid/99921
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038962
Third Party Advisory
VDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr1
Vendor Advisory